201 Practice Questions
Prepare for 201 with more than an answer.
- Exam fee
- $180 USD
- Level
- Administrator
- Valid for
- 3 years
Domains covered on the exam 8
- Troubleshoot basic virtual server connectivity issues20%
- Troubleshoot basic hardware issues10%
- Troubleshoot basic performance issues10%
- Troubleshoot basic device management connectivity issues10%
- Open a support ticket with F510%
- Identify and report current device status10%
- Maintain system configuration15%
- Manage existing system and application services15%
- 1
The command to save the running configuration to the startup configuration files from the TMOS shell (tmsh) is:
save /sys _____.Show answer details
Correct answer: B
The correct tmsh command to save the running configuration from memory to the configuration files on disk (e.g., bigip.conf) is
save /sys config. This is equivalent to clicking the 'Save' button in the Configuration Utility. - 2
An administrator is investigating a hardware issue on a BIG-IP appliance and wants to review log files specifically related to the chassis, fans, and power supplies. In which log file would this information typically be found?
Show answer details
Correct answer: D
The
/var/log/platform_checklog file is populated by theplatform_checkservice, which periodically polls hardware components like fans, power supplies, and temperature sensors. This log is the primary location for identifying and troubleshooting physical hardware component failures or warnings. - 3
A new administrator is trying to understand the relationship between different configuration objects on a BIG-IP. Which of the following statements accurately describes the hierarchy?
Show answer details
Correct answer: C
This describes the correct hierarchy. A Virtual Server is the traffic listener. It directs traffic to a Pool, which is a logical group of backend servers. The members of the pool are the actual backend services, defined by a Node (the server's IP address) and a specific service port (e.g., 80, 443).
- 4
During a security audit, it was discovered that remote administrative access via SSH is being authenticated against a central RADIUS server. However, the system is not using NTP for time synchronization. Why is this a security and operational risk?
Show answer details
Correct answer: B
While some authentication protocols are time-sensitive, the most significant risk in this context is log correlation. For security incident response and general troubleshooting, having accurate, synchronized timestamps across all devices (BIG-IP, RADIUS server, firewalls, etc.) is critical. Without NTP, the BIG-IP's clock can drift, making it impossible to build an accurate timeline of events during an investigation.
- 5
The following diagram shows a typical SSL offloading scenario. Which numbered segment represents the traffic that is processed by a Server SSL profile?
graph LR Client -- 1. Encrypted --> BIGIP[BIG-IP] BIGIP -- 2. Decrypted --> Server[Web Server]Show answer details
Correct answer: C
The diagram shows SSL offloading, where the BIG-IP decrypts client traffic. A Client SSL profile handles segment 1. Since segment 2 is decrypted (plain HTTP), no Server SSL profile is needed. A Server SSL profile would only be used if the connection from the BIG-IP to the web server also needed to be re-encrypted.
- 6
An F5 administrator is configuring a new virtual server for a critical application and needs to ensure that if the primary persistence method fails, a backup method is used. The primary requirement is Source Address persistence, with a fallback to SSL session ID persistence if no source address match is found. How should this be configured on the virtual server?
Show answer details
Correct answer: C
The BIG-IP system is designed to handle this scenario explicitly. The 'Default Persistence Profile' is always checked first. If no persistence record is found using the default profile, the system then checks the 'Fallback Persistence Profile'. This allows for a layered approach to session persistence without requiring iRules or custom profiles for this common use case.
- 7
A BIG-IP device in a high-availability (HA) pair is rebooted into the End User Diagnostics (EUD) utility to check for potential hardware faults. After the tests complete, the administrator needs to save the results for analysis and for a potential F5 support case. What is the correct procedure to obtain the EUD output?
Show answer details
Correct answer: B
The standard F5 procedure for collecting EUD results involves using a USB flash drive. The EUD utility has a built-in function to detect the drive and save the diagnostic log file, which can then be easily transferred to another machine for review or uploaded to F5 Support.
- 8
A web application is experiencing intermittent slowness. The administrator suspects the issue is related to how the BIG-IP is handling HTTP content, possibly with compression or caching. Standard dashboard statistics do not provide enough detail. To investigate further, the administrator decides to use
tcpdump. Whichtcpdumpflag is essential for viewing the unencrypted HTTP payload on a virtual server that has a Client SSL profile applied?Show answer details
Correct answer: C
The
:pmodifier used with the-i 0.0interface tellstcpdumpto capture traffic on the client-side of the flow after it has been decrypted by the Client SSL profile. This allows the administrator to see the raw, unencrypted application layer data (e.g., HTTP headers and payload) as it is processed by TMM, which is crucial for troubleshooting application-level performance issues. - 9
An administrator cannot access the BIG-IP Configuration Utility (GUI) via a self-IP address that is normally used for management. SSH access to the same self-IP is working correctly. The administrator suspects a Port Lockdown setting is the cause. Where in the Configuration Utility would the administrator verify and modify the Port Lockdown settings for the self-IP?
Show answer details
Correct answer: B
Port Lockdown is a security feature configured on a per-self-IP basis. To check or change this setting, the administrator must navigate to Network > Self IPs, select the specific self-IP in question, and then review the 'Port Lockdown' setting. SSH is likely allowed while HTTPS is not.
- 10
When preparing to open a support case with F5 for a complex application delivery issue, what is the single most important diagnostic file that should be generated and uploaded to iHealth before contacting support?
Show answer details
Correct answer: C
A qkview file is a comprehensive snapshot of the BIG-IP system's configuration, logs, and real-time status. F5 Support engineers rely on this file as the primary source of information for troubleshooting. Uploading it to iHealth provides an initial automated analysis and makes the data readily available to the support team, significantly speeding up the diagnostic process.
